EUVD-2024-49957
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 14 Nov 2024. Evidence sources: cisa_kev.
- ENISA score
- 9.2 · CVSS 4.0
- Advisory evidence
- 2 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2024-0405Kwetsbaarheden verholpen in Palo Alto Expedition
